All tips
DKIM 2 min read

Why DKIM signatures break in transit

Anything that modifies signed headers or the body invalidates the signature. Mailing lists are the usual culprit, and there is no way to sign around them.

A DKIM signature covers a set of headers and a hash of the body. Change either after signing and verification fails. Most breakage traces to a small number of causes.

Mailing lists

Discussion lists routinely prefix the subject with a tag, append an unsubscribe footer to the body, or both. Either edit invalidates the signature. Well-configured lists work around this by rewriting the From header to the list's own address, which makes the message the list's to authenticate rather than yours.

Gateways and appliances

Security gateways that rewrite URLs for click protection, append disclaimers, or convert the body's encoding will break signatures on the way through. If you run one on the outbound path, it must sign after its own modifications, not before.

The l= tag is not the answer

The optional l= tag limits how much of the body the signature covers, so appended footers do not break it. It also lets an attacker append arbitrary content to a signed message and keep the signature valid. Do not use it.

Other common causes

  • Signing a header that is later added or duplicated by an intermediate hop.
  • Strict canonicalisation (c=simple) with any hop that adjusts whitespace or refolds headers. Use relaxed.
  • A key rotated out of DNS before queued mail drained.
  • A DNS lookup failure for the selector at verification time, which is a temporary error rather than a signature problem.

Before assuming your signing is broken, verify a message you received from yourself that took a single hop. If that passes, the problem is on the path, not in your configuration.

Look up a DKIM selector and key strength
dkimtroubleshootingmailing-lists